ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Daily Briefing › 6 Oct 2026

ITSECURITY.GURU

Daily Briefing

Today's outlook

Citrix NetScaler flaw is being exploited now; Chrome ships five critical fixes

Good morning. Patch Citrix first. CISA lists CVE-2026-88779 on its Known Exploited Vulnerabilities catalog and records it as known to be exploited. Citrix's advisory covers NetScaler ADC 13.1 up to the fix in 13.1-37.282; the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H carries a base score of 7.5, an availability-only impact reachable over the network with no authentication or user interaction. CISA directs stakeholders to apply mitigations in line with the vendor advisory and BOD 26-04, or discontinue use if no mitigation is available.

Google patched five critical Chrome flaws, each scored CVSS 9.6 against the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H: CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382. Google's advisory lists the fix in Chrome 155.0.8059.39. None is on CISA's KEV catalog. Update the browser and confirm the build.

Exploitation in the wild, by outlet. BleepingComputer reported hackers are exploiting stored cross-site scripting flaws in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to install backdoors and create rogue admin accounts. BleepingComputer also reported Atlassian is warning of a critical arbitrary file-access flaw in self-hosted Data Center products including Confluence, Jira and Bitbucket. And BleepingComputer reported that on day one of Pwn2Own Ireland 2026 researchers exploited 32 zero-days, hacking the Samsung Galaxy S26 twice and earning $388,500.

Breaches and campaigns. BleepingComputer reported ASOS confirmed a data breach after attackers sent unauthorized push notifications through its app and claimed to have stolen customer data from its Snowflake environment. SecurityWeek reported the FBI removed an Accenture contractor over a breach it blames on a missed patch, which exposed personal data of thousands of bureau employees. The Record reported South Korean officials believe AI agents and a Chinese cybersecurity tool were used to breach at least seven financial institutions, exposing data on at least 68,000 people. BleepingComputer and The Hacker News reported a human-operated phishing platform using fake ChatGPT, Gemini, Claude and Perplexity ad portals to steal credentials and MFA codes via browser-in-browser attacks.

Also note: CISA published an advisory for Hitachi Energy RTU500 end-of-life CMU firmware 9.x, from findings reported by Dragos; and Schneier on Security, citing 404Media, reports a cyber-weapons manufacturer is exploiting an iOS flaw to bypass the automatic reboot that secures an idle iPhone after 72 hours.

Zoom out: Only the Citrix flaw is listed as exploited; the five critical Chrome bugs are not on CISA's catalog.

Vulnerability in focus

CVE-2026-88779 — Citrix. CVSS 7.5 CISA lists it as known to be exploited.

Affected: citrix-adc.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

What we're tracking

  • The Register: Anthropic reconfigures its cool kids security program Read it
  • BleepingComputer: Ninja Forms plugin flaw exploited to hack WordPress sites Read it
  • The Hacker News: Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes Read it
  • The Record: Alleged ATM malware creator appears in Nebraska court after arrest Read it

Sources

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →